Selected work

Real engineering, proven under pressure

These are real enterprise projects our engineers designed and delivered — firewall migrations, high-availability networks and multi-site identity platforms across finance, government, defence and multi-site corporates. The engineering discipline behind them — architecture, security policy, identity, segmentation — is exactly what we now deliver remotely to Gulf businesses. What once needed an engineer on-site, modern cloud, firewall and management tooling let us run over secure remote access.

9
Anonymized reference projects
4
Cloud / DevOps platforms delivered
100%
Cloud builds defined as code
COP29
CTO-led network infrastructure

Delivered on-site across our first decade; delivered remotely today. The skill is the same — the difference is that firewalls, servers, cloud and identity are now administered the way modern teams already work: over secure, least-privilege remote access.

Case studies

Real scope, not slideware

Grouped by the three services we deliver. Client names are withheld and replaced with a sector descriptor; every architecture and figure below is drawn directly from the delivered project — we describe what was built, and we don't publish anything we cannot stand behind.

Pillar 01

Managed IT & Cloud Operations

Proactive remote monitoring, cloud management and end-user support — off your plate.

Explore the service →
Multi-Branch Corporate Group

Five branches unified on one managed platform

A corporate group running five separate branch offices needed them to behave as one business. We consolidated identity, mail and servers into a single managed platform and linked every site with encrypted connectivity.

120
Users unified
5
Branches interconnected
S2S VPN
Secure site links
What we engineered
  • Central domain (Active Directory), mail and server platform
  • 120 users consolidated across 5 branches
  • Site-to-site (S2S) VPN interconnect between branches
Active DirectoryMicrosoftSite-to-Site VPN
Defence & Industrial Manufacturer

Identity, mail and security foundation for a defence manufacturer

A defence-sector manufacturer needed a complete identity and mail foundation, hardened behind a managed firewall. We designed and stood up the directory, mail and perimeter-security stack — the same platform work we now run remotely on managed and cloud servers.

AD + Mail
Identity & mail platform
Checkpoint
Managed perimeter firewall
What we engineered
  • Active Directory domain, file and mail platform design
  • Perimeter-security hardening with a Checkpoint firewall
  • Directory, identity and access foundation for a regulated sector
Active DirectoryCheckpointMicrosoftIdentity & access
Systems Integration Group

Standardised, centrally-managed IT across ~20 sites

A fast-growing integration group had inconsistent IT across sites. We standardised the environment around a central platform so every office ran the same supportable, manageable build — the consistency-at-scale discipline behind everything we manage remotely today.

~20
Sites on one standard
1
Central managed platform
What we engineered
  • ~20 sites standardised on a single consistent build
  • Centrally supportable, manageable environment
  • Repeatable configuration across every office
Active DirectoryStandardisationEndpoints

Pillar 02

DevOps-as-a-Service

A remote DevOps team on demand — pipelines, automation and infrastructure as code.

Explore the service →
Regional Fintech — Payment Gateway

Cloud-native, PCI-aligned platform for a payment gateway

A regional payment-gateway provider needed a production AWS platform that scales with real payment traffic and stands up to payments-grade security. We designed and delivered the entire environment as code — Amazon EKS with an Istio service mesh, Karpenter and KEDA autoscaling, CI/CD, full observability and HSM-backed key management. This is remote-native cloud engineering, delivered end to end.

100%
Infrastructure as code (Terraform)
EKS
Kubernetes + Istio service mesh
HSM
Payment-grade key management
What we engineered
  • Full AWS platform defined end-to-end in Terraform — no manual provisioning
  • Amazon EKS with Istio, Karpenter and KEDA event-driven autoscaling; microservices shipped via Helm
  • CI/CD with self-hosted GitLab runners across dev and production
  • Observability stack: Prometheus, Grafana, Loki, Tempo and OpenSearch
  • Payments security: AWS CloudHSM, WAF, External Secrets Operator + KMS, IPsec VPN to the banking partner
AWSTerraformKubernetes (EKS)IstioKarpenterHelmGitLab CIPrometheus / Grafana
Fintech — Digital Payments (UAE / MENAP market)

Cost-efficient Kubernetes autoscaling for a UAE payments fintech

A digital-payments fintech operating in the UAE and wider MENAP region — a PCI-DSS, 3-D Secure payments environment — needed a platform that absorbs spiky transaction volume without paying for idle capacity. We built it on Amazon EKS with Karpenter so nodes scale to real demand, backed by managed AWS data services and GitLab CI/CD, delivered and operated entirely remotely. (A different client and pattern to the payment-gateway build above: cost-driven autoscaling rather than service-mesh security.)

UAE / MENAP
Serves the Gulf region
PCI-DSS
Regulated payments environment
Karpenter
Autoscales to burst traffic
What we engineered
  • Amazon EKS with Karpenter node autoscaling — capacity follows real payment demand
  • Managed AWS data services: RDS, ElastiCache Redis, S3 and SQS
  • Entire AWS footprint defined as code in Terraform
  • GitLab CI/CD pipelines for repeatable, automated deploys
AWSTerraformKubernetes (EKS)KarpenterRDSS3SQSGitLab CI
B2B SaaS — AI Email Automation

Monorepo CI/CD and multi-account AWS for a SaaS platform

An AI-powered email-automation and shared-inbox SaaS needed a fast, repeatable path from commit to production across many microservices. We built multi-account AWS infrastructure as code and an Azure DevOps monorepo pipeline with affected-service detection — so only changed services rebuild and deploy.

11
Microservices on ECS Fargate
2
Isolated multi-account AWS envs
Monorepo
Affected-service CI/CD
What we engineered
  • Azure DevOps CI/CD over a pnpm/Moon monorepo — only changed services rebuild
  • 11 microservices on AWS ECS Fargate behind public and internal ALBs with Cloud Map service discovery
  • Entire AWS footprint as Terraform code across isolated Dev/Demo accounts
  • Managed services: RDS, ElastiCache Redis, S3, SQS, OpenSearch and Temporal Cloud
  • Centralised observability (Grafana, Loki, Fluent Bit) and security gates (gitleaks, ClamAV) on every run
AWS ECS FargateTerraformAzure DevOpsDockerRDSRedisSQSOpenSearchTemporal
Multi-Tenant SaaS — POS & ERP

Kubernetes and Helm platform for a multi-tenant SaaS

A multi-tenant POS and ERP SaaS — many tenant companies on one Laravel codebase, each on its own subdomain — needed to run reliably on Kubernetes with per-tenant isolation. We containerised it, packaged it as a Helm chart, and automated zero-downtime rollouts with autoscaling and wildcard TLS.

5
Container images from one codebase
2→30
Pods autoscaled per tier
Wildcard
Automated TLS per tenant
What we engineered
  • Decomposed a monolithic Laravel app into 5 purpose-built container images (multi-stage, Alpine)
  • Templated the whole platform as a custom Helm chart (HPA, PDB, config/secret split), dev and prod values
  • CI/CD publishing to GitHub Container Registry with rolling, zero-downtime deploys
  • nginx ingress + cert-manager wildcard TLS for multi-tenant subdomain isolation
  • Managed MySQL with a read replica, Redis, and S3-compatible object storage
DockerKubernetesHelmHPAnginx Ingresscert-managerGHCRRedisMySQL

Pillar 03

Cybersecurity & Network Management

Enterprise security and connectivity, configured and managed remotely.

Explore the service →
Non-Bank Credit Institution — Finance

Perimeter firewall migration for a regulated lender

A regulated financial lender needed to move off an ageing perimeter firewall without losing its security posture. We migrated to a modern FortiGate platform and rebuilt the policy set from the ground up — the firewall configuration, migration and hardening work we now do remotely.

FG-201
FortiGate platform migrated to
ASA → FGT
Legacy firewall migration
What we engineered
  • Migration from a legacy Cisco ASA to FortiGate FG-201
  • Full security-policy configuration and hardening
  • Rule-set rebuilt on a least-privilege basis
Fortinet FortiGateCisco ASAFirewall policy
National Sports Federation — Government

High-availability network architecture for a government body

A national government body required a resilient, segmented network that could not go down. We designed a clustered, high-availability architecture with defence-in-depth firewalling and full VLAN segmentation — the same network design and firewall policy we now build and manage remotely.

Firewalls in HA cluster
VLAN
Full network segmentation
HA
No single point of failure
What we engineered
  • Resilient, high-availability core network architecture
  • Defence-in-depth firewalling (2 perimeter, 2 internal edge)
  • VLAN segmentation and secure remote access design
HA / ClusteringVLAN segmentationVPNFirewall policy

Engineering leadership

Architecture credentials at global scale

Our CTO was lead architect and installation manager for the passive network infrastructure — structured cabling and the fibre-optic backbone — of COP29, the UN Climate Change Conference (Baku, 2024). The same engineering discipline behind an event of that scale now underpins the remote services we deliver to Gulf businesses every day.

Technologies used across these projects

AWS·Terraform·Kubernetes·Fortinet·Cisco·Checkpoint·Microsoft / Active Directory

Put this team on your infrastructure

Managed IT and cloud operations, DevOps-as-a-Service, or cybersecurity and network management — all delivered remotely from our Baku center, on Gulf Standard Time. Tell us what you need and we'll scope it.